PT-2025-30006 · Tutorials Website · Employee Management System

Ary52

·

Published

2025-07-17

·

Updated

2025-09-26

·

CVE-2025-11030

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Tutorials-Website Employee Management System versions prior to 611887d8f8375271ce8abc704507d46340837a60
Description A flaw exists in the Tutorials-Website Employee Management System that allows for improper authorization. The issue is located in an unknown function within the /admin/all-applied-leave.php file, related to the HTTP Request Handler component. The attack can be initiated remotely, and details about the exploit are publicly available. The product uses a rolling release system, so specific version information is not disclosed.
Recommendations Update to a version prior to 611887d8f8375271ce8abc704507d46340837a60.

Exploit

Fix

Improper Authorization

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2025-11030

Affected Products

Employee Management System